Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format
2025-10-02T10:15:39.053
2025-10-24T14:34:37.740
Analyzed
CVSSv3.1: 8.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | canonical | lxd | < 5.21.4 | Yes |
| Application | canonical | lxd | < 6.5 | Yes |